❌

Normal view

OCC Rules Regarding the Availability of OCC Information

The Office of the Comptroller of the Currency (OCC) is proposing changes to its rules on information disclosure. The proposal would clarify the process for obtaining OCC approval to disclose non- public OCC information and allow for the disclosure of confidential supervisory information without OCC approval in certain circumstances, provided that applicable safeguards are observed. It also refines the OCC's process for requesting records under the Freedom of Information Act (FOIA), amends the rules to provide for expedited process of FOIA requests, and makes other structural and conforming changes.

Anti-Money Laundering and Countering the Financing of Terrorism Programs

The Board of Governors of the Federal Reserve System (the Board) is inviting comment on a proposed rule that would require its supervised banks to establish and maintain effective anti-money laundering and countering the financing of terrorism (AML/CFT) programs reasonably designed to identify, assess, and mitigate risks of illicit finance. Among other changes, this proposed rule would ensure that Board-supervised banks establish and maintain effective AML/CFT programs that are intended to better achieve the purposes of the Bank Secrecy Act (BSA), culminating in the development of highly useful information related to illicit financial transactions for law enforcement and national security agencies. The amendments are intended to align with changes to AML/CFT program requirements proposed by the Financial Crimes Enforcement Network (FinCEN) to implement provisions of the Anti-Money Laundering Act of 2020 (AML Act) and corresponding changes proposed by the Office of the Comptroller of the Currency (OCC), Federal Deposit Insurance Corporation (FDIC), and the National Credit Union Administration (NCUA) (collectively, "the Agencies") on April 10, 2026.

One-two punch delivered in global operation disrupts cybercrime "assembly line"

24 June 2026 at 21:03

International authorities and a raft of private technology companies say they have disrupted a cybercrime β€œassembly line” that allowed crooks to collect millions of login credentials and steal more than $47 million in ransom payments and by other fraudulent means.

The crux of the operation was the simultaneous targeting of two unrelated tools that are widely used in various online scams. The first is Amadey, a malware-as-a-service platform for compromising devices and delivering malicious payloads for ransomware and other scams. Amadey has been observed in the wild since at least 2018 and was seen last year abusing GitHub as it collected system information from infected devices and installed customized payloads. The second tool was StealC, an infostealer-as-a-service platform that collects credentials, authentication cookies, cryptocurrency wallets, browser extensions, and files whose names match customer-defined patterns.

Severing a critical link in the cybercrime chain

Amadey and StealC are separate tools that are run independently of each other. Given their widespread use, however, many customers use both in their individual cybercrime activities. The tools also, it turns out, relied on some of the same underlying infrastructure to run. Microsoft said it made this determination after analyzing the tools using AI. This insight allowed Microsoft attorneys to seek an order disrupting both at the same time.

Read full article

Comments

Β© Alex Schmidt / Getty Images

Botnet of more than 17 million devices dismantled

29 May 2026 at 18:46

Authorities in the Netherlands said they dismantled a botnet that comprised more than 17 million devices and were managed by 200 servers in a joint operation by the police and the National Cyber Security Center.

The action, announced Thursday, came about after a security researcher reported the sprawling network to authorities. The host infrastructure was located in the Netherlands.

Used for criminal purposes

β€œThe police then seized several botnet servers from a hosting provider for investigation,” the NCSC said. β€œThe botnet was taken offline by the provider because it was used for criminal purposes.”

Read full article

Comments

Β© Aurich Lawson / Ars Technica

❌